Hi Brett,
>> With testshib, starting on sp.testshib.org and entering our entity ID, we go to our Gluu instance and are correctly presented with a login screen on Gluu and after logging in, go back to testshib SP where we get an error about failed validation.
If you get 'failed validation' from testShib, I think you can check logs from testshib; it should have indication of failure.
>> While testing our own SP (built using pac4j-saml in a java project), we keep running into an error when using SP-initiated flow of: Validation of protocol message signature failed.
Generally it means... there are SAML cert differences between what you are putting in IDP ( from SP side ) and what it's actually there inside SP. May be open a new ticket on that?
>> Our SP is configured with the cert from shibboleth
I think I didn't understand the term 'cert from shibboleth'
>> although we have noticed that there are 2 certs that might be used for signing
Which two certs?